{"cve":"CVE-2026-96275","enrichment":{"created":"2026-09-23T17:00:08.047305+00:00","updated":"2026-09-23T17:00:08.047311+00:00","vendors":[]},"mitre":{"cpes":["cpe:/o:redhat:enterprise_linux:10","cpe:/o:redhat:enterprise_linux:7","cpe:/o:redhat:enterprise_linux:8","cpe:/o:redhat:enterprise_linux:9"],"created":"2026-09-23T15:01:38.344000+00:00","description":"A malicious or compromised Flatpak repository can write attacker-controlled content to arbitrary locations on the host filesystem via extract_extra_data(). On system installs, the write happens as root. Two issues combine: `files/extra` is resolved via path operations that follow symlinks, and blob names from `xa.extra-data-sources` are not sanitized against `..` traversal.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":8.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"cvssV4_0":{}},"mitre_repo_path":"cves/2026/96xxx/CVE-2026-96275.json","references":["https://access.redhat.com/security/cve/CVE-2026-96275","https://bugzilla.redhat.com/show_bug.cgi?id=2539416","https://github.com/flatpak/flatpak/security/advisories/GHSA-fqx6-vh4p-42cg"],"title":"Flatpak: flatpak: arbitrary write access as root via extra-data extraction","updated":"2026-09-23T16:08:11.613000+00:00","vendors":["redhat","redhat$PRODUCT$enterprise_linux"],"weaknesses":["CWE-22"]},"nvd":{"cpes":[],"created":"2026-09-23T15:17:32.180000+00:00","description":"A malicious or compromised Flatpak repository can write attacker-controlled content to arbitrary locations on the host filesystem via extract_extra_data(). On system installs, the write happens as root. Two issues combine: `files/extra` is resolved via path operations that follow symlinks, and blob names from `xa.extra-data-sources` are not sanitized against `..` traversal.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":8.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"cvssV4_0":{}},"nvd_repo_path":"2026/CVE-2026-96275.json","references":["https://access.redhat.com/security/cve/CVE-2026-96275","https://bugzilla.redhat.com/show_bug.cgi?id=2539416","https://github.com/flatpak/flatpak/security/advisories/GHSA-fqx6-vh4p-42cg"],"title":null,"updated":"2026-09-23T19:40:10+00:00","vendors":[],"weaknesses":["CWE-22"]},"opencve":{"changes":[{"created":"2026-09-23T15:15:00+00:00","data":[{"details":{"new":"A malicious or compromised Flatpak repository can write attacker-controlled content to arbitrary locations on the host filesystem via extract_extra_data(). On system installs, the write happens as root. Two issues combine: `files/extra` is resolved via path operations that follow symlinks, and blob names from `xa.extra-data-sources` are not sanitized against `..` traversal.","old":null},"type":"description"},{"details":{"new":"Flatpak: flatpak: arbitrary write access as root via extra-data extraction","old":null},"type":"title"},{"details":["redhat","redhat$PRODUCT$enterprise_linux"],"type":"first_time"},{"details":{"added":["CWE-22"],"removed":[]},"type":"weaknesses"},{"details":{"added":["cpe:/o:redhat:enterprise_linux:10","cpe:/o:redhat:enterprise_linux:7","cpe:/o:redhat:enterprise_linux:8","cpe:/o:redhat:enterprise_linux:9"],"removed":[]},"type":"cpes"},{"details":{"added":["redhat","redhat$PRODUCT$enterprise_linux"],"removed":[]},"type":"vendors"},{"details":{"added":["https://access.redhat.com/security/cve/CVE-2026-96275","https://bugzilla.redhat.com/show_bug.cgi?id=2539416","https://github.com/flatpak/flatpak/security/advisories/GHSA-fqx6-vh4p-42cg"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV3_1":{"score":8.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"eb9dbf6e-6ab9-4018-88ce-77564f2522d1"}],"cpes":{"data":["cpe:/o:redhat:enterprise_linux:10","cpe:/o:redhat:enterprise_linux:7","cpe:/o:redhat:enterprise_linux:8","cpe:/o:redhat:enterprise_linux:9"],"providers":["mitre"]},"created":{"data":"2026-09-23T15:01:38.344000+00:00","provider":"mitre"},"description":{"data":"A malicious or compromised Flatpak repository can write attacker-controlled content to arbitrary locations on the host filesystem via extract_extra_data(). On system installs, the write happens as root. Two issues combine: `files/extra` is resolved via path operations that follow symlinks, and blob names from `xa.extra-data-sources` are not sanitized against `..` traversal.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":8.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"provider":"mitre"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{},"provider":null},"kev":{"data":{},"provider":null},"ssvc":{"data":{},"provider":null},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://access.redhat.com/security/cve/CVE-2026-96275","https://bugzilla.redhat.com/show_bug.cgi?id=2539416","https://github.com/flatpak/flatpak/security/advisories/GHSA-fqx6-vh4p-42cg"],"providers":["mitre","nvd"]},"title":{"data":"Flatpak: flatpak: arbitrary write access as root via extra-data extraction","provider":"mitre"},"updated":{"data":"2026-09-23T15:01:38.344000+00:00","provider":"mitre"},"vendors":{"data":["redhat","redhat$PRODUCT$enterprise_linux"],"providers":["mitre"]},"weaknesses":{"data":["CWE-22"],"providers":["mitre","nvd"]}}}